GitHub acknowledged that the actions of an employee compromised 3,800 repositories—he had installed a malicious extension for VS Code.
GitHub reports the hacking of nearly 3,800 repositories after installing a malicious VS Code extension
*Brief:*
As a result of an incident involving a compromised Visual Studio Code plugin, about 3,800 GitHub repositories were at risk. The company removed the extension from the marketplace, isolated the employee’s workspace, and began an investigation.
What happened
1. Detection – overnight, administrators noticed that one of their employees’ work devices had been breached.
2. Identification of malware – it turned out the cause was a infected VS Code extension.
3. Response measures
* The dangerous extension was removed from GitHub’s official marketplace.
* The employee’s workspace was isolated and disconnected from the network.
* An investigation was launched immediately.
> “We discovered and contained the breach of an employee’s device linked to a compromised VS Code extension. We removed the malicious version of the extension, isolated the workspace, and promptly began responding to the incident… During the attack only data from internal GitHub repositories were exfiltrated,” said the platform team.
Scale of damage
* Company estimate: about 3,800 repositories were compromised.
* It is currently confirmed that data leaked only from internal GitHub repositories – there was no public code disclosure.
Who’s behind the attack
* The TeamPCP group previously announced on a specialized forum that they had access to GitHub source code and “about 4,000 private-code repositories.”
* They demanded at least $50,000, threatening to publish the data if their demands were not met.
* TeamPCP has already participated in large-scale supply‑chain attacks (GitHub, PyPI, NPM, Docker) and the Mini Shai‑Hulud campaign that targeted OpenAI employees.
Why it matters
- VS Code is one of the most popular code editors. Plugins are downloaded from the official marketplace, but this isn’t the first time malicious extensions have amassed millions of downloads.
- GitHub serves over 4 million organizations, including 90% of Fortune 100 companies, and more than 180 million developers.
- In total, the platform hosts more than 420 million code repositories.
What GitHub is doing
1. Removing the malicious extension from the marketplace.
2. Isolating and protecting the compromised device.
3. Conducting a full incident investigation and damage assessment.
4. Strengthening security measures to prevent similar attacks in the future.
Conclusion: GitHub confirmed that around 3,800 repositories were breached due to a malicious VS Code extension, but there is no confirmation yet of any public code leak. The company is taking protective steps and investigating the incident.
Comments (0)
Share your thoughts — please be polite and stay on topic.
Log in to comment